Is there a way to create a container in Phantom using results from a Splunk search?
The Splunk app for Phantom can poll Splunk and create containers. Alternatively, the Phantom App for Splunk can be configured to send events from Splunk to Phantom.
See:
https://splunkbase.splunk.com/app/3411/
https://my.phantom.us/4.8/docs/app_reference/phantom_splunk
Ideally this would occur as the result of a user entering data into a dashboard. So, there is not really an event occurring. I am not sure we need to store the entered data in an index.